Associated Malware Groups
The filename is associated with the malware groups:
- System Back Door
- Cloaked Malware
File Behavior
WMISRPC.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Can communicate with other computer systems using HTTP protocols
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Injects code into other processes
- Registers a Dynamic Link Library File
- Copies files
- Uses Instant Messaging to communicate without the user's knowledge
- Uses embeded Instant Message Channel Settings
- Found on infected systems and resists interrogation by security products
WMISRPC.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry auto start to load Program on Boot up
- Deleted as a process from disk
- Terminated as a Process
- Registered as a Dynamic Link Library File
- Copied to multiple locations on the system
Country Of Origin
The filename WMISRPC.EXE was first seen on Nov 7 2009 in the following geographical regions of the Prevx community:
- EGYPT on Nov 7 2009
- The EUROPEAN UNION on Nov 7 2009
- PUERTO RICO on Nov 7 2009
- INDIA on Nov 12 2009
- The UNITED STATES on Nov 14 2009
- ROMANIA on Nov 15 2009
- INDONESIA on Nov 18 2009
File Name Aliases
WMISRPC.EXE can also use the following file names:
- MVC-PICTURE011.JPG_WWW.MYFILEHD.COM
- DPLYRM~1.EXE
- ZR.EXE
- ZE.EXE
- WM.EXE
- HP.EXE
- KG.EXE
- FA.EXE
- IK.EXE
- CA.EXE
- LW.EXE
- WB.EXE
- BN.EXE
- MT.EXE
- PQ.EXE
- TZ.EXE
- BO.EXE
- EM.EXE
- LX.EXE
- MH.EXE
- WA.EXE
- XF.EXE
- JT.EXE
- VB.EXE
- RQ.EXE
- YE.EXE
- TA.EXE
- WK.EXE
- LZ.EXE
- IJ.EXE
- ZB.EXE
- UY.EXE
- NE.EXE
- JO.EXE
- MP.EXE
- TW.EXE
- OA.EXE
- IO.EXE
- BT.EXE
- QXZV85.EXE@
- QXZV28.EXE@
- 19541339.EXE
Filesizes
The following file size has been seen:
- 141,824 bytes
- 188,416 bytes
- 128,512 bytes
- 196,608 bytes
- 149,504 bytes
- 135,680 bytes
File Type
The filename WMISRPC.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.